CVE-2024-0522
Allegro RomPager HTTP POST Request cross-site request forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?action=delete of the component HTTP POST Request Handler. The manipulation of the argument username leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 4.30 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250692. NOTE: The vendor explains that this is a very old issue that got fixed 20 years ago but without a public disclosure.
Se encontró una vulnerabilidad en Allegro RomPager 4.01. Ha sido clasificada como problemática. Una función desconocida del archivo usertable.htm?action=delete del componente HTTP POST Request Handler es afectada por esta vulnerabilidad. La manipulación del argumento username conduce a cross-site request forgery. Es posible lanzar el ataque de forma remota. La actualización a la versión 4.30 puede solucionar este problema. Se recomienda actualizar el componente afectado. El identificador de esta vulnerabilidad es VDB-250692. NOTA: El proveedor explica que se trata de un problema muy antiguo que se solucionó hace 20 años pero sin revelarlo públicamente.
Es wurde eine problematische Schwachstelle in Allegro RomPager 4.01 ausgemacht. Es geht dabei um eine nicht klar definierte Funktion der Datei usertable.htm?action=delete der Komponente HTTP POST Request Handler. Mit der Manipulation des Arguments username mit unbekannten Daten kann eine cross-site request forgery-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Ein Aktualisieren auf die Version 4.30 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-14 CVE Reserved
- 2024-01-14 CVE Published
- 2024-01-23 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.250692 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Allegrosoft Search vendor "Allegrosoft" | Rompager Search vendor "Allegrosoft" for product "Rompager" | 4.01 Search vendor "Allegrosoft" for product "Rompager" and version "4.01" | - |
Affected
|